Your backups should be as carefully protected as your project.
ReviveDB uses the least access it can, stores recovery points in the EU, and never copies your secret values.
The short version
No shared database password
Connect with Supabase OAuth. The connection is encrypted.
Temporary read-only access
Each backup gets its own short-lived login, then it is removed.
No changes to your live project
The backup login reads what it needs. It cannot change your data.
Stored in the EU
Cloudflare R2, EU jurisdiction, AES-256 at rest. Processing in Amsterdam.
Backups are checked
Every database backup is restored into isolated PostgreSQL and compared before it becomes available.
Deletion removes the copies
Delete a project and its recovery points go with it. Retried for 30 days if storage is down.
What a backup can reach
Each backup runs with its own read-only login. This is the full extent of it.
Read
- Your database and Auth data, including rows that RLS protects.
- Storage files, bucket settings and Edge Function code.
Never
- Write to your database, create roles, replicate, or give itself more rights.
- Copy the values of Edge Function or Vault secrets.
- Keep working after the backup.
Security documents
Security questions?
Ask us about access, retention, deletion, subprocessors or security reviews.